Newtonsoft.Json before 13.0.1 is associated with a denial-of-service advisory tracked as CVE-2024-21907 and GHSA-5crp-9r3c-p9vr [S1][S2]. Advisory sources describe risk when deeply nested or otherwise attacker-controlled JSON reaches affected Newtonsoft.Json serialization or deserialization paths, which can exhaust CPU, memory, or process stack depending on how the application uses the library [S1][S3].
Why this matters
Newtonsoft.Json is common in .NET APIs, webhook handlers, queue consumers, background workers, and shared libraries. A vulnerable package version in a deployed artifact is not the same as confirmed exploitability, but it is strong patch-triage evidence because the vulnerable code can sit on input boundaries that parse attacker-controlled JSON.
Covered by FixVibe
FixVibe's GitHub repo scans flag NuGet project, central package, packages.config, and lockfile entries that resolve Newtonsoft.Json to a version affected by CVE-2024-21907 / GHSA-5crp-9r3c-p9vr.
Remediation
Upgrade Newtonsoft.Json to 13.0.1 or newer everywhere it is restored into deployed apps, services, workers, or shared libraries [S1][S2]. Regenerate lockfiles, run dotnet restore, rebuild deployed artifacts, and verify that production images or deployment packages no longer carry the affected version.
Where untrusted JSON is accepted, also review parser and serializer entry points and set an appropriate MaxDepth or equivalent input-depth limit where compatibility allows [S1][S4]. Rerun the FixVibe GitHub repo scan after updating dependencies and lockfiles.
